mirror of
https://github.com/fscotto/infra.git
synced 2026-07-29 16:20:01 +00:00
171 lines
5.5 KiB
YAML
171 lines
5.5 KiB
YAML
---
|
|
- name: Ensure GNOME desktop user config directories exist
|
|
tags: [dotfiles, dotfiles:desktop, gnome]
|
|
ansible.builtin.file:
|
|
path: "{{ item }}"
|
|
state: directory
|
|
owner: "{{ username }}"
|
|
group: "{{ user_group }}"
|
|
mode: "0755"
|
|
loop:
|
|
- "{{ user_home }}/.config"
|
|
- "{{ user_home }}/.config/autostart"
|
|
- "{{ user_home }}/.local"
|
|
- "{{ user_home }}/.local/bin"
|
|
- "{{ user_home }}/.bashrc.d"
|
|
- "{{ user_home }}/.tmux"
|
|
- "{{ user_home }}/.tmux/bin"
|
|
- "{{ user_home }}/.tmux/plugins"
|
|
|
|
- name: Ensure GNOME desktop private directories exist
|
|
tags: [dotfiles, dotfiles:desktop, gnome]
|
|
ansible.builtin.file:
|
|
path: "{{ item.path }}"
|
|
state: directory
|
|
owner: "{{ username }}"
|
|
group: "{{ user_group }}"
|
|
mode: "{{ item.mode }}"
|
|
loop:
|
|
- path: "{{ user_home }}/.gnupg"
|
|
mode: "0700"
|
|
- path: "{{ user_home }}/.ssh"
|
|
mode: "0700"
|
|
- path: "{{ user_home }}/.local/state/ssh/sockets"
|
|
mode: "0700"
|
|
|
|
- name: Copy GNOME desktop dotfiles
|
|
tags: [dotfiles, dotfiles:desktop, gnome]
|
|
ansible.builtin.copy:
|
|
src: "{{ playbook_dir }}/../dotfiles/desktop/{{ item.src }}"
|
|
dest: "{{ user_home }}/{{ item.dest }}"
|
|
owner: "{{ username }}"
|
|
group: "{{ user_group }}"
|
|
mode: "{{ item.mode }}"
|
|
loop: "{{ desktop_common_dotfiles | default([]) }}"
|
|
loop_control:
|
|
label: "{{ item.dest }}"
|
|
|
|
- name: Copy GNOME Emacs desktop dotfiles
|
|
tags: [dotfiles, dotfiles:desktop, emacs, gnome]
|
|
ansible.builtin.copy:
|
|
src: "{{ playbook_dir }}/../dotfiles/desktop/{{ item.src }}"
|
|
dest: "{{ user_home }}/{{ item.dest }}"
|
|
owner: "{{ username }}"
|
|
group: "{{ user_group }}"
|
|
mode: "{{ item.mode }}"
|
|
loop: "{{ desktop_emacs_dotfiles | default([]) }}"
|
|
when: emacs_enabled | default(false) | bool
|
|
loop_control:
|
|
label: "{{ item.dest }}"
|
|
|
|
- name: Configure GNOME gpg-agent for Fedora
|
|
tags: [dotfiles, dotfiles:desktop, git, gnome]
|
|
ansible.builtin.copy:
|
|
dest: "{{ user_home }}/.gnupg/gpg-agent.conf"
|
|
content: |
|
|
pinentry-program /usr/bin/pinentry-gnome3
|
|
enable-ssh-support
|
|
default-cache-ttl 600
|
|
max-cache-ttl 7200
|
|
owner: "{{ username }}"
|
|
group: "{{ user_group }}"
|
|
mode: "0600"
|
|
notify: Reload GNOME gpg-agent
|
|
|
|
- name: Render GNOME git configuration with private values
|
|
tags: [dotfiles, dotfiles:desktop, git, gnome]
|
|
ansible.builtin.template:
|
|
src: desktop/.gitconfig.j2
|
|
dest: "{{ user_home }}/.gitconfig"
|
|
owner: "{{ username }}"
|
|
group: "{{ user_group }}"
|
|
mode: "0644"
|
|
|
|
- name: Check whether SSH host ed25519 key exists on GNOME desktop
|
|
tags: [services, gnome]
|
|
ansible.builtin.stat:
|
|
path: /etc/ssh/ssh_host_ed25519_key
|
|
register: gnome_ssh_host_ed25519_key
|
|
when:
|
|
- (host_sshd_settings | default({})) | length > 0
|
|
or (host_sshd_allow_users | default([])) | length > 0
|
|
|
|
- name: Generate missing SSH host keys on GNOME desktop
|
|
tags: [services, gnome]
|
|
ansible.builtin.command: ssh-keygen -A
|
|
changed_when: true
|
|
when:
|
|
- (host_sshd_settings | default({})) | length > 0
|
|
or (host_sshd_allow_users | default([])) | length > 0
|
|
- not gnome_ssh_host_ed25519_key.stat.exists
|
|
|
|
- name: Require authorized SSH keys before disabling password authentication on GNOME desktop
|
|
tags: [services, gnome]
|
|
ansible.builtin.assert:
|
|
that:
|
|
- (host_authorized_ssh_keys | default([])) | length > 0
|
|
fail_msg: >-
|
|
SSH password authentication is disabled for this host, but no authorized SSH
|
|
keys are defined. Set host_authorized_ssh_keys via vault variables before
|
|
applying this configuration.
|
|
when:
|
|
- "'sshd' in (host_enabled_services | default([]))"
|
|
- (host_sshd_settings | default({})).PasswordAuthentication | default('yes') == 'no'
|
|
|
|
- name: Ensure GNOME desktop user authorized_keys file exists
|
|
tags: [services, dotfiles, gnome]
|
|
ansible.builtin.file:
|
|
path: "{{ user_home }}/.ssh/authorized_keys"
|
|
state: touch
|
|
owner: "{{ username }}"
|
|
group: "{{ user_group }}"
|
|
mode: "0600"
|
|
when: (host_authorized_ssh_keys | default([])) | length > 0
|
|
|
|
- name: Manage GNOME desktop user authorized SSH keys exclusively
|
|
tags: [services, dotfiles, gnome]
|
|
ansible.posix.authorized_key:
|
|
user: "{{ username }}"
|
|
key: "{{ host_authorized_ssh_keys | join('\n') }}"
|
|
state: present
|
|
exclusive: true
|
|
manage_dir: false
|
|
when: (host_authorized_ssh_keys | default([])) | length > 0
|
|
|
|
- name: Apply SSH daemon settings on GNOME desktop
|
|
tags: [services, gnome]
|
|
ansible.builtin.lineinfile:
|
|
path: /etc/ssh/sshd_config
|
|
regexp: '^\s*{{ item.key }}\s+'
|
|
line: "{{ item.key }} {{ item.value }}"
|
|
state: present
|
|
validate: "sshd -t -f %s"
|
|
notify: Reload SSH service
|
|
loop: "{{ host_sshd_settings | default({}) | dict2items }}"
|
|
loop_control:
|
|
label: "{{ item.key }}"
|
|
when: (host_sshd_settings | default({})) | length > 0
|
|
|
|
- name: Restrict SSH login to allowed GNOME desktop users
|
|
tags: [services, gnome]
|
|
ansible.builtin.lineinfile:
|
|
path: /etc/ssh/sshd_config
|
|
regexp: '^\s*AllowUsers\s+'
|
|
line: "AllowUsers {{ host_sshd_allow_users | join(' ') }}"
|
|
state: present
|
|
validate: "sshd -t -f %s"
|
|
notify: Reload SSH service
|
|
when: (host_sshd_allow_users | default([])) | length > 0
|
|
|
|
- name: Apply host firewalld rich rules on GNOME desktop
|
|
tags: [services, packages, gnome]
|
|
ansible.posix.firewalld:
|
|
rich_rule: "{{ item }}"
|
|
permanent: true
|
|
immediate: true
|
|
state: enabled
|
|
loop: "{{ host_firewalld_rich_rules | default([]) }}"
|
|
loop_control:
|
|
label: "{{ item }}"
|
|
when: workstation_firewall_backend | default('firewalld') == 'firewalld'
|